Privacy Policy

Last updated 2026-09-29

This policy explains what personal data Censory processes, why, where it is stored, how long we keep it, and the rights you have. For the documents you upload, your law firm is the data controller and Censory acts as a processor on your instructions.

Who is responsible

For your account and billing data, Censory is the controller. For the documents you upload, which contain your clients' personal data, your law firm is the controller and Censory is a processor acting only on your documented instructions, governed by a Data Processing Agreement.

What we process

Account: email, password hash, login sessions. Billing: subscription, credits, and your Polar customer id. Documents: the files you upload, the censored outputs, detected regions, and document metadata. Usage: pages processed and credits spent. For consented users only: training samples (page images plus detected labels).

Legal basis

Account and billing: performance of a contract (Art. 6(1)(b)). Document processing: carried out on your firm's instructions as a processor. Training data: your explicit consent (Art. 6(1)(a), and Art. 9(2)(a) for special-category content), which you can withdraw at any time.

AI detection & third parties

To detect personal data we process each page in two steps: an OCR step locates the text on the page, and an AI model then classifies which of it is personal data. Both steps run on EU-resident hosts: stage-1 OCR on RunPod, Inc. serverless GPU endpoints configured to run in EU regions only, and stage-2 classification through OpenRouter, Inc. routed in-region in the EU at the account level. Neither endpoint publishes its region in a form our software can read, so both are recorded as documented configuration assertions rather than as something we can prove from a hostname. The classification requests are sent with zero-data-retention and data-collection-denied flags, so neither the gateway nor the upstream model provider may store them or train on them. These are two separate guarantees: where a request is routed is not the same question as whether it is retained. The requests are transient — we do not retain the page image for the detection call itself, and the only persistence is the opt-in training path. The sub-processors who can reach document content are RunPod, Inc. (OCR), OpenRouter, Inc. (classification) and Cloudflare, Inc. (R2 storage); Polar (billing), Brevo (transactional email) and PostHog (product analytics) reach account data only and never your documents. The maintained register, recording what each one receives, is available from [email protected].

Where your data lives

Censory's own servers run inside the European Union (Fly.io, Frankfurt), and so do both AI detection hosts — see the section above. Documents and outputs are stored in Cloudflare R2 object storage scoped to your account, in a bucket created with EU jurisdiction. One distinction we would rather state than gloss over: that jurisdiction is fixed when the bucket is created and is not something our software can read back, so it is not yet covered by the start-up residency check that already guards the detection hosts and product analytics. We are completing that last step and will update this section when the check covers storage too — at which point any drift would fail a deployment instead of passing quietly. No part of the detection pipeline currently relies on a non-EU provider.

How long we keep it

Uncensored originals are deleted by default the moment you finalize a document. Censored outputs and metadata stay in your library until you delete them or close your account. Training samples are kept for up to 24 months. Account and billing records are kept while your account is active and as long as the law requires afterward.

Your rights

You can access and export all your data (Profile → Download all my data), correct it, delete individual documents, delete your training data, or delete your entire account (Profile → Danger zone). Clients whose data appears inside an uploaded document should contact the law firm that holds it.

Security

Uploads go through our authenticated backend; storage credentials never reach the browser. The censored output is non-reconstructive: redacted text is removed from the file, not just covered. If a personal-data breach affecting documents or account data ever occurs, we notify the affected law firm or organisation **without undue delay** after becoming aware of it, with what we know about the nature of the breach, the categories and approximate number of records involved, the likely consequences and the measures taken — our obligation as a processor under Art. 33(2) GDPR. Where we are the controller (your account and billing data) we notify the supervisory authority within 72 hours where the breach is likely to present a risk, and you directly where it is likely to present a high risk (Art. 33(1) and Art. 34). We will not wait for certainty before telling you: a report that turns out to be smaller than feared is a better outcome than a late one.

Cookies

This site uses one necessary cookie to remember the language you picked. If you accept analytics in the cookie banner, we also count which pages and features are used; that is off unless you turn it on, and it never involves your documents. The banner itself stores your choice in your browser and sends nothing to anyone. The Censory application at live.censory.app has no banner: it needs an account, and the Terms of Service you accept at sign-up cover the storage it uses. Analytics there is on by default and linked to your account; you can turn it off at any time in Profile → Privacy & data.

Read the full cookie policy

Contact & complaints

For privacy questions or to exercise your rights, contact us at [email protected]. You also have the right to complain to your supervisory authority; in Romania that is ANSPDCP (dataprotection.ro).